Aggregator
Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms
Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms
CVE-2025-10892 | Google Chrome up to 140.0.7339.185 V8 integer overflow
CVE-2025-10891 | Google Chrome up to 140.0.7339.185 V8 integer overflow
CVE-2025-10890 | Google Chrome up to 140.0.7339.185 V8 information disclosure
CVE-2025-39890 | Linux Kernel up to 6.6.93/6.12.33/6.15.2 wifi ath12k_service_ready_ext_event memory leak
CVE-2025-39889 | Linux Kernel up to 5.15.180/6.1.134/6.6.87/6.12.24/6.14.3 Bluetooth information disclosure
CVE-2024-58241 | Linux Kernel up to 6.11.5 Bluetooth privilege escalation
Hackers Can Bypass EDR by Downloading a Malicious File as an In-Memory PE Loader
A sophisticated technique that allows attackers to execute malicious code directly in memory is gaining traction, posing a significant challenge to modern Endpoint Detection and Response (EDR) solutions. This method, which involves an in-memory Portable Executable (PE) loader, enables a threat actor to run an executable within an already trusted process, effectively bypassing security checks […]
The post Hackers Can Bypass EDR by Downloading a Malicious File as an In-Memory PE Loader appeared first on Cyber Security News.
Casino company Boyd Gaming hacked, employee data stolen
The Gentleman
You must login to view this content
OnePlus OxygenOS Vulnerability Lets Apps Access SMS Data Without User Permission
A newly disclosed flaw in OnePlus OxygenOS lets any app on a device read SMS and MMS messages without asking the user. Tracked as CVE-2025-10184, the issue stems from a permission bypass in the Telephony content provider (com.android.providers.telephony). Normally, apps must hold the Android READ_SMS permission and prompt the user before accessing text messages. In […]
The post OnePlus OxygenOS Vulnerability Lets Apps Access SMS Data Without User Permission appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
The Gentleman
You must login to view this content
Attackers Exploit BMC Firmware Vulnerabilities to Bypass Signature Verification
In January 2025, Supermicro released patches addressing critical vulnerabilities in its Baseboard Management Controller (BMC) firmware validation logic. Despite these updates, subsequent research has uncovered bypass techniques that undermine signature verification and even compromise the BMC’s Root of Trust (RoT). Among these, CVE-2024-10237 stemmed from a logical vulnerability in the validation process, allowing malicious firmware […]
The post Attackers Exploit BMC Firmware Vulnerabilities to Bypass Signature Verification appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Warlock
You must login to view this content
Код, который плавит золото. Как одна строчка в программе привела к уничтожению 200-летнего наследия
Weaponized Malwarebytes, LastPass, Citibank, SentinelOne, and Others on GitHub Deliver Malware
In recent weeks, cybersecurity teams have observed a surge in malicious GitHub repositories masquerading as legitimate security and financial software. Threat actors have crafted convincing forks of projects bearing names like Malwarebytes, LastPass, Citibank, and SentinelOne, populated with trojanized installers and scripts that deliver stealthy malware payloads. These repositories exploit the trust developers place in […]
The post Weaponized Malwarebytes, LastPass, Citibank, SentinelOne, and Others on GitHub Deliver Malware appeared first on Cyber Security News.